CCM — AES CCM mode encryption

Counter with cipher block chaining - message authentication code (CCM) mode is an authenticated encryption algorithm designed to provide both authentication and confidentiality (encryption/decryption) during data transfer.

The main features of CCM are:

AES CCM combines counter (CTR) mode encryption and cipher block chaining - message authentication code (CBC-MAC) authentication. The CCM terminology message authentication code (MAC) is called message integrity check (MIC) in Bluetooth terminology, and also in this document.

Figure 1. CCM Overview


CCM generates an encrypted keystream that is applied to input data using the XOR operation and generates an M byte MAC field in one operation. CCM and RADIO can be configured to work synchronously. CCM will encrypt in time for transmission and decrypt after receiving bytes into memory from the radio. All operations can complete within the packet RX or TX time. CCM on this device is implemented to support the Bluetooth requirements and the algorithm as defined in IETF RFC3610, and depends on the AES-128 block cipher. A description of the CCM algorithm can also be found in NIST Special Publication 800-38C. The Bluetooth specification describes the configuration of counter mode blocks and encryption blocks to implement compliant encryption for Bluetooth Low Energy.

CCM uses EasyDMA to read/write additional authenticated data, plain text and cipher text.

Two operations are supported:

All operations are done in compliance with the Bluetooth Core Specification, as well as IEEE 802.15.4.

Shared resources

The CCM shares the same AES module as the AAR and ECB peripherals. The ECB will always have the lowest priority. If an operation is aborted due to a conflict among the shared resources, an ERROR event will be generated.

Additionally, the CCM shares registers and other resources with the peripherals that have the same ID as the CCM. See Peripherals with shared ID for more information.

Encryption and decryption

CCM supports both packet encryption and decryption.

The following table shows the different CCM input/output and parameters supported by the CCM module for encryption and decryption:

Table 1. CCM Parameters
ParameterValid inputDescription
M0, 4, 6, 8, 10, 12, 14, 16Number of bytes in the authentication field
L2 (fixed)Number of bytes in the length field
l(a)0-65279Number of bytes in additional authenticated data
l(m)0-(65535 - M)Number of bytes in the message to authenticate and encrypt
l(c)0-65535Number of bytes in the encrypted message; l(m) + M bytes
al(a) number of bytesAdditional authenticated data
ml(m) number of bytesMessage to authenticate and encrypt
cl(c) number of bytesEncrypted message
In addition to the parameters listed above, the CCM requires two sets of data: a 128-bit key and a 128-bit nonce. These are supplied via dedicated register interfaces: KEY.VALUE registers for the 128-bit key, and NONCE.VALUE registers for the 128-bit nonce. The 128-bit key in the KEY.VALUE registers is stored in reverse byte order relative to the payload. For example, using the sample session key from the Bluetooth Core Specification v5.4, Volume 6, Part C, chapter 1.2:
  • Session Key (SK): 99AD1B5226A37E3E058E3B8E27C2C666
The KEY.VALUE registers are populated as follows:The same reverse byte order is used for the NONCE.VALUE registers. For the packet example "3. Data packet1" with the following values:
  • IV: DEAFBABEBADCAB24
  • Direction Bit: 1
  • Packet Counter: 1
The NONCE.VALUE registers are populated as follows:
Note: Although the NONCE in the example above is 13 bytes, it must be written as a 16-byte value with the first 3 bytes zero-padded.
Note: The KEY and NONCE byte order is reversed compared to the NRF52 and NRF53 series devices.

Encryption

During packet encryption, CCM will read the unencrypted packet located in memory at the address specified in register IN.PTR, encrypt the packet and append an M byte long message authentication code (MAC) field to the packet.

The message to authenticate and encrypt (m) and additional authenticated data (a) are included in the MAC generation. The first byte in the packet header can be masked by configuring the ADATAMASK register. This is useful for Bluetooth header masking. For protocols other than Bluetooth, the ADATAMASK register must be set to 0xFF for correct CCM operation; the reset value is configured to support Bluetooth.

Encryption is started by triggering the START task with the MODE register set to Encryption. The END event will be generated when packet encryption is completed.

The AES CCM will modify the l(c) output field of the packet to adjust for the appended MAC field, that is, add MODE.MACLEN bytes to l(m), and store the resulting packet back into memory at the locations specified in the OUT.PTR list, as illustrated in the following figure. The maximum length of l(m) plus MODE.MACLEN cannot exceed 65535 bytes.

Figure 2. Encryption

AES CCM packet encryption

If the following occurs, the ERROR event is generated, the CCM stops, and the ERRORSTATUS register will report the type of error that triggered the ERROR event:
  • The IN.PTR job list ends before reading out the complete CCM data structure
  • The OUT.PTR job list ends before writing out the complete encrypted CCM data structure
  • The CCM is not able to operate fast enough to run concurrently with the RADIO as the RADIO transmits the encrypted packet.
  • The EasyDMA engine encounters an error, see EasyDMA and ERROR event

Any values of l(m) and l(a) are allowed. If encrypting empty packets, i.e. l(m) = l(a) = 0, no encryption will take place; the END event is generated, and CCM operation is stopped.

For Bluetooth (MODE.PROTOCOL=Ble), valid packets with 0 payload (l(a) is larger than 0 but l(m) is 0) will not be authenticated but instead moved unmodified through the AES CCM peripheral, and thus no MAC will be generated.

For IEEE 802.15.4 (MODE.PROTOCOL=Ieee802154), valid packets with 0 payload (l(a) is larger than 0 but l(m) is 0) will be authenticated, and thus a MAC will be generated as part of the output data.

Decryption

During packet decryption, CCM will read the encrypted packet located in memory at the address specified in the IN.PTR pointer, decrypt the packet, authenticate the packet's MAC field and generate the appropriate MAC status.

The encrypted message in (c), is decrypted and authenticated together with additional authenticated data (a) and then matched against the decrypted MAC value. The decrypted MAC value is part of (c). Bits in the first byte of the data can be masked away before calculating the MAC value by configuring the ADATAMASK register. This is useful for Bluetooth header masking. For protocols other than Bluetooth, the ADATAMASK register must be set to 0xFF for correct CCM operation; the reset value is configured to support Bluetooth.

Decryption is started by triggering the START task with the MODE register set to FastDecryption.

CCM will write the l(m) value of the decrypted packet to the location provided in OUT.PTR, and then store the decrypted packet into memory at the locations given by the OUT.PTR list as illustrated in the following figure.

Figure 3. Decryption

AES CCM packet decryption

For Bluetooth (MODE.PROTOCOL=Ble), CCM is only able to authenticate messages where l(c) is at least MACLEN+1 bytes long. If l(c) is less than MACLEN+1, CCM will generate an END event and clear the MACSTATUS (indicating MAC check failure). Furthermore, empty packets (l(c)=0) will be moved unmodified through the AES CCM peripheral even though ERROR event shall be generated. In any other case that leads to a failed MACSTATUS or an ERROR event, the contents of the job addresses given in OUT.PTR are undefined.

For IEEE 802.15.4 (MODE.PROTOCOL=Ieee802154), CCM will also perform authentication on messages where only ADATA is present (i.e. l(m)=0 and l(a)>0). In this case MACSTATUS reflects the result of the authentication. If l(c)<MACLEN, then the ERROR event is generated, and the contents of the locations given in OUT.PTR are undefined.

If the following occurs, the ERROR event is generated, and CCM is stopped.
  • The IN.PTR job list ends before reading out the complete CCM data structure
  • The OUT.PTR job list ends before writing out the complete decrypted CCM data structure
  • The EasyDMA engine encounters an error, see EasyDMA and ERROR event
If the IN.PTR or OUT.PTR job lists do not end before the complete encrypted/decrypted CCM data structures are read, the END event is generated and CCM operation is stopped.

Encrypting packets in radio transmit mode

When the AES CCM is encrypting a packet at the same time as the radio is transmitting it, the radio must read the encrypted packet from the same memory location as the AES CCM is writing to.

The OUT.PTR pointer in the AES CCM must therefore point to the same memory location as the PACKETPTR pointer in the radio, see Example configuration of encryption during radio transmission.

Figure 4. Example configuration of encryption during radio transmission

Configuration of encryption

The START task must be triggered by RADIO READY event to ensure that the payload is encrypted in time for radio transmission. This is illustrated in the following figure, using a PPI connection between RADIO.EVENTS_READY and CCM.TASKS_START.

Figure 5. Radio transmission with encryption using a PPI connection

Radio transmission with encryption using a PPI connection.

Decrypting packets received by the radio

To decrypt a packet received by the radio immediately upon its reception, CCM can be started when the RADIO PAYLOAD event is generated. The packet is decrypted when the CCM.END event is generated. Typically, CCM will decrypt the packet before or during the reception of the CRC. However, if the packet is large and the bitrate is high, CCM will not finish before the PHYEND event, but shortly afterward. After the CCM.END event is generated; the MACSTATUS can be checked.

AES CCM must therefore operate on the same memory location as RADIO, as illustrated in the following figure.

Figure 6. Example configuration of CCM for decrypting a packet as it is received by the RADIO


CCM data structure

The input and output data structures are located in memory specified by IN.PTR and OUT.PTR respectively.

Both IN.PTR and OUT.PTR point to a scatter/gather job list. This job list must contain all the fields listed in the attribute field table. Each job list must be terminated with a 0 filled job entry. If either of the IN.PTR or OUT.PTR job list is not terminated, then the behavior of CCM is undefined.

The job list consists of one or more job entries each containing a 32-bit address field, an 8-bit attribute field, and a 24-bit length field. A job list ends with a zero-filled job entry. The EasyDMA job list example below illustrates a job list that points to three different memory sections with varying lengths. The data pointed to by the job list is fed into the module to be processed according to the CCM operation. Job entries with a length greater than one byte are processed in little endian order.
Figure 7. EasyDMA job list example

EasyDMA job list example

The attribute field identifies the job and must be set according to the following table.
Table 2. Attribute field
AttributeValue
Alen11
Mlen12
Adata13
Mdata14

EasyDMA and ERROR event

The CCM implements an EasyDMA with scatter/gather mechanism for reading and writing to memory.

In cases where the CPU and other EasyDMA enabled peripherals are accessing the same RAM block at the same time, a high level of bus collisions may cause too slow operation for correct on the fly encryption. In this case the ERROR event will be generated.

EasyDMA will have finished accessing the memory when the END event is generated.

If the IN.PTR and the OUT.PTR are not pointing to memory with DMA connectivity, an EasyDMA transfer may result in a HardFault or memory corruption. See Memory for more information about the different memory regions.

For instances supporting DMA error detection, the ERRORSTATUS register will report if a bus error has occurred during DMA access.

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA

CCM00 : S
CCM00 : NS

GLOBAL

0x5004A000
0x4004A000

USSSANo

AES CCM mode encryption CCM00, running of HCLKCORE

Configuration

InstanceDomainConfiguration

CCM00 : S
CCM00 : NS

GLOBAL

Does not support on-the-fly decryption.

Register overview

RegisterOffsetTZDescription
TASKS_START0x000

Start encryption/decryption. This operation will stop by itself when completed.

TASKS_STOP0x004

Stop encryption/decryption

TASKS_RATEOVERRIDE0x008

Override DATARATE setting in MODE register with the contents of the RATEOVERRIDE register for any ongoing encryption/decryption

SUBSCRIBE_START0x080

Subscribe configuration for task START

SUBSCRIBE_STOP0x084

Subscribe configuration for task STOP

SUBSCRIBE_RATEOVERRIDE0x088

Subscribe configuration for task RATEOVERRIDE

EVENTS_END0x104

Encrypt/decrypt complete or ended because of an error

EVENTS_ERROR0x108

CCM error event

PUBLISH_END0x184

Publish configuration for event END

PUBLISH_ERROR0x188

Publish configuration for event ERROR

INTENSET0x304

Enable interrupt

INTENCLR0x308

Disable interrupt

MACSTATUS0x400

MAC check result

ERRORSTATUS0x404

Error status

ENABLE0x500

Enable

MODE0x504

Operation mode

KEY.VALUE[n]0x510

128-bit AES key

NONCE.VALUE[n]0x520

13-byte NONCE vector

Only the lower 13 bytes are used

IN.PTR0x530

Input pointer

Points to a job list containing unencrypted CCM data structure in Encryption mode

Points to a job list containing encrypted CCM data structure in Decryption mode

OUT.PTR0x538

Output pointer

Points to a job list containing encrypted CCM data structure in Encryption mode

Points to a job list containing decrypted CCM data structure in Decryption mode

RATEOVERRIDE0x544

Data rate override setting.

ADATAMASK0x548

CCM adata mask.

TASKS_START

Address offset: 0x000

Start encryption/decryption. This operation will stop by itself when completed.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_START

Start encryption/decryption. This operation will stop by itself when completed.

Trigger

1

Trigger task

TASKS_STOP

Address offset: 0x004

Stop encryption/decryption

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_STOP

Stop encryption/decryption

Trigger

1

Trigger task

TASKS_RATEOVERRIDE

Address offset: 0x008

Override DATARATE setting in MODE register with the contents of the RATEOVERRIDE register for any ongoing encryption/decryption

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_RATEOVERRIDE

Override DATARATE setting in MODE register with the contents of the RATEOVERRIDE register for any ongoing encryption/decryption

Trigger

1

Trigger task

SUBSCRIBE_START

Address offset: 0x080

Subscribe configuration for task START

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task START will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

SUBSCRIBE_STOP

Address offset: 0x084

Subscribe configuration for task STOP

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task STOP will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

SUBSCRIBE_RATEOVERRIDE

Address offset: 0x088

Subscribe configuration for task RATEOVERRIDE

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task RATEOVERRIDE will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

EVENTS_END

Address offset: 0x104

Encrypt/decrypt complete or ended because of an error

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_END

Encrypt/decrypt complete or ended because of an error

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_ERROR

Address offset: 0x108

CCM error event

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_ERROR

CCM error event

NotGenerated

0

Event not generated

Generated

1

Event generated

PUBLISH_END

Address offset: 0x184

Publish configuration for event END

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event END will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

PUBLISH_ERROR

Address offset: 0x188

Publish configuration for event ERROR

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event ERROR will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1S

END

Write '1' to enable interrupt for event END

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1S

ERROR

Write '1' to enable interrupt for event ERROR

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1C

END

Write '1' to disable interrupt for event END

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1C

ERROR

Write '1' to disable interrupt for event ERROR

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

MACSTATUS

Address offset: 0x400

MAC check result

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

MACSTATUS

The result of the MAC check performed during the previous decryption operation

CheckFailed

0

MAC check failed

CheckPassed

1

MAC check passed

ERRORSTATUS

Address offset: 0x404

Error status

Bit number313029282726252423222120191817161514131211109876543210
IDAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

ERRORSTATUS

Error status when the ERROR event is generated

NoError

0

No errors have occurred

PrematureInptrEnd

1

End of INPTR job list before CCM data structure was read.

PrematureOutptrEnd

2

End of OUTPTR job list before CCM data structure was read.

EncryptionTooSlow

3

Encryption of the unencrypted CCM data structure did not complete in time.

DmaError

4

Bus error during DMA access.

ENABLE

Address offset: 0x500

Enable

Bit number313029282726252423222120191817161514131211109876543210
IDAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

ENABLE

Enable or disable CCM

Disabled

0

Disable

Enabled

2

Enable

MODE

Address offset: 0x504

Operation mode

Bit number313029282726252423222120191817161514131211109876543210
IDDDDCCCBBAA
Reset 0x0000000100000000000000000000000000000001
IDR/WFieldValue IDValueDescription
A

RW

MODE

The mode of operation to be used. The settings in this register apply when the CRYPT task is triggered.

Encryption

0

AES CCM packet encryption mode

Decryption

1

This mode will run CCM decryption in the speed of the DATARATE field.

This enumerator is deprecated.

FastDecryption

2

AES CCM decryption mode.

3

B

RW

PROTOCOL

Protocol and packet format selection

Ble

0

Bluetooth Low Energy packet format

Ieee802154

1

802.15.4 packet format

2

3

C

RW

DATARATE

Radio data rate that the CCM shall run synchronous with

125Kbit

0

125 Kbps

250Kbit

1

250 Kbps

500Kbit

2

500 Kbps

1Mbit

3

1 Mbps

2Mbit

4

2 Mbps

4Mbit

5

4 Mbps

D

RW

MACLEN

CCM MAC length (bytes)

M0

0

M = 0

This is a special case for CCM* where encryption is required but not authentication

M4

1

M = 4

M6

2

M = 6

M8

3

M = 8

M10

4

M = 10

M12

5

M = 12

M14

6

M = 14

M16

7

M = 16

KEY.VALUE[n]

Address offset: 0x510 + (n × 0x4)

128-bit AES key

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

VALUE

AES 128-bit key value, bits (32*(i+1))-1 : (32*i)

NONCE.VALUE[n]

Address offset: 0x520 + (n × 0x4)

13-byte NONCE vector

Only the lower 13 bytes are used

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

VALUE

NONCE value, bits (32*(n+1))-1 : (32*n)

IN

IN EasyDMA channel

IN.PTR

Address offset: 0x530

Input pointer

Points to a job list containing unencrypted CCM data structure in Encryption mode

Points to a job list containing encrypted CCM data structure in Decryption mode

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

PTR

Input pointer

OUT

OUT EasyDMA channel

OUT.PTR

Address offset: 0x538

Output pointer

Points to a job list containing encrypted CCM data structure in Encryption mode

Points to a job list containing decrypted CCM data structure in Decryption mode

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

PTR

Output pointer

RATEOVERRIDE

Address offset: 0x544

Data rate override setting.

Override value to be used instead of the setting of MODE.DATARATE. This override value applies when the RATEOVERRIDE task is triggered.

Note: The override is only applied when operating in BLE Long Range mode.
Bit number313029282726252423222120191817161514131211109876543210
IDAAA
Reset 0x0000000200000000000000000000000000000010
IDR/WFieldValue IDValueDescription
A

RW

RATEOVERRIDE

Data rate override setting.

125Kbit

0

125 Kbps

500Kbit

2

500 Kbps

1Mbit

3

1 Mbps

2Mbit

4

2 Mbps

4Mbit

5

4 Mbps

ADATAMASK

Address offset: 0x548

CCM adata mask.

Bitmask for the first adata byte. The masking is done before MAC generation/authentication.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAA
Reset 0x000000E300000000000000000000000011100011
IDR/WFieldValue IDValueDescription
A

RW

ADATAMASK

CCM adata mask.